NGINX Plus and NGINX Open Source HTTP/3 QUIC Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in NGINX Plus and NGINX Open Source versions 1.25.0 prior to 1.25.4, as well as in NGINX Plus R3x. When the experimental HTTP/3 QUIC module is enabled, undisclosed requests can lead to the termination of NGINX worker processes. This disruption causes a temporary outage as the NGINX process restarts.
Impact
Exploitation of this vulnerability causes NGINX worker processes to crash, leading to a denial-of-service condition where traffic is disrupted until the processes are restarted.
Remediation
Users can upgrade to NGINX versions 1.25.4 or 1.27.0. For NGINX Plus, the latest version is recommended. If an immediate upgrade is not possible, the HTTP/3 module can be disabled in the NGINX configuration.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
